Your RSA-2048 keys break in 2030. Find every one of them before attackers do.
Malicious package

multi-reqsnpm

multi-reqs is a confirmed malicious npm package (MAL-2026-12797) that steals credentials and exfiltrates sensitive data (malicious versions 1.0.0, 1.0.1, 1.0.2…). Do not install it — remove it immediately and rotate any exposed credentials.

Malicious code in multi-reqs (npm)

MAL-2026-12797
Immediate action
Remove the package, then rotate any secrets the build/runtime could reach.
npm uninstall multi-reqs

What this malware does

The package's default export accepts (token, password) arguments and POSTs them, formatted as a Discord embed titled 'Yeni Hesap Bilgisi' with fields '🔑 Token' and '🔒 Şifre', to a hardcoded discord.com webhook URL. The destination is non-configurable, and any consumer that imports multi-reqs and invokes the default function forwards those credentials to an author-controlled Discord channel. Parameter naming and the Turkish 'Hesap Yönetim Sistemi' (Account Management System) framing indicate the module is designed to be consumed or bundled into other code as a credential-harvesting shim.

Malicious versions

4 flagged
1.0.01.0.11.0.21.0.3

Indicators of compromise (SHA-256)

2c03bde07a2a75531f18734b6986de0c59cd7d75400c665e4e059fb18b42996f
633363514a8110d1ba6af50ac4431fa5e3bccb5e3692222d856747f10e6397ac
a3d70b2617fc2d0158533bc541e04b68263a1e07ee2057c439c43ec40b073ad4
38937963f906d0bf3b4dac24a1a45f574aeb53cd2f268ffb9730d88bedf50bce

Detection & response playbook

Credential / info stealer
  1. Find it

    Scan your lockfiles (package-lock.json, pnpm-lock.yaml, yarn.lock, requirements.txt, poetry.lock, etc.) and build artifacts for multi-reqs (4 malicious versions). O3 Security's supply-chain scanner checks every dependency against known-malicious package intelligence at install time and in CI, flagging multi-reqs across your stack and pipelines.

  2. If you installed it — respond

    multi-reqs is built to steal secrets, so assume every credential the build or runtime could read is compromised. Remove it from your project and lockfile, then rotate ALL exposed secrets — npm/registry tokens, cloud keys, CI/CD secrets, SSH keys, and any .env values — from a known-clean machine. Audit logs for unauthorized use of those credentials.

  3. Did it already run?

    If multi-reqs was ever installed, its post-install/runtime payload may have already executed. O3's L7 egress monitoring and runtime eBPF sensors detect the credential exfiltration or command-and-control callback after install and block the malicious outbound channel, so you catch and contain the actual compromise — not just the presence of the package.

  4. How O3 protects you

    O3 blocks multi-reqs before install through its supply-chain scanner, and if it has already run, detects and severs the exfiltration or C2 callback at runtime through L7 egress monitoring and eBPF.

Frequently asked questions

No. multi-reqs on npm has been identified as a malicious package (versions 1.0.0, 1.0.1, 1.0.2, 1.0.3 flagged). It should be removed immediately — do not install or keep it in your dependency tree.

Campaign

IN-MAL-2026-014971IN-MAL-2026-014973IN-MAL-2026-014974IN-MAL-2026-015797

References

Credits

  • Amazon Inspector · finder

Detect & block this

O3 blocks multi-reqs-class packages before install and in CI — and if it already ran, its runtime egress monitoring catches the credential exfiltration and severs the channel.

Explore

multi-reqs (npm) malicious package — MAL-2026-12797 | O3 Security